Impact
The vulnerability permits escalation of privileges through improper handling of content in the DOM within the Content Processes component. The flaw lies in how the application processes DOM elements, potentially allowing an attacker, and it is categorized under CWE‑269 and CWE‑653, indicating an authorization flaw that could be leveraged to bypass expected access controls.
Affected Systems
Mozilla Firefox and Mozilla Thunderbird are affected. All releases prior to version 153 contain the flaw; the issue was fixed in Firefox 153 and Thunderbird 153, so any older installation remains vulnerable.
Risk and Exploitability
The CVSS score of 8.8 marks the flaw as high, but the EPSS score of less than 1% indicates a low probability of exploitation at present and it has not been reported in the CISA KEV catalog. Based on the description, the likely attack vector is the delivery of malicious content that triggers the DOM parsing process, though specific exploitation conditions are not provided in the advisory. The flaw requires the component to process content in a way that alters privilege boundaries, and would need the target environment to handle such content.
OpenCVE Enrichment